Comment on SSH keys stolen by stream of malicious PyPI and npm packages

<- View Parent
CmdrKeen@lemmy.today ⁨11⁩ ⁨months⁩ ago

IDK, virus scanners and malware detectors could do these things before AI.

You could search for stuff like directly accessing the ~.ssh directory, or any invocations of wget or curl to download external scripts and run them through an interpreter and flag those for closer inspection.

If you want to get fancier, automate installing packages in an isolated environment (like a container or VM) and keep track of every file system access and network request they make.

Sure, eventually they’ll figure out ways to obfuscate those things, too, but it could at least prevent people from doing things in such blatantly obvious ways.

source
Sort:hotnewtop